employee security awareness - wecc security awareness... · • staff responsibilities •...

20
Employee Security Awareness Tuesday, April 9, 2019 Louis Stramaglio IT Ops Supervisor

Upload: others

Post on 19-May-2020

8 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

Employee Security Awareness

Tuesday, April 9, 2019

Louis StramaglioIT Ops Supervisor

Page 2: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• What is the greatest vulnerability in your organization?

oElectronic Security Perimetero IT NetworkoOT NetworkoPermissionsoPhysical Security

2

Are You Vulnerable?

Page 3: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• Employees

• End users

• Clients

• Customers

• Contractors

3

YES!

Page 4: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

Does your company have an Employee Security Awareness Program?

4

Question

Page 5: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• Understand and comply with company security policies and procedures

• Be appropriately trained in the rules of behavior for the systems and applications to which they have access

• Work with management to meet training needs• Keep end users aware of actions they can take

to better protect their company’s information

5

IT Security Program

Page 6: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

1. Security Policies• Designed to protect the data• Business needs• Known risks

2. Define responsibilities• Who is responsible• Staff responsibilities• IT/Security responsibilities

3. Establish Processes• Monitor the program• Review results• IRP(Incident Response Plan)

6

Security Program Contents

Page 7: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

Do you believe your current Employee Security Awareness Program has Management Buy-in?

7

Question

Page 8: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• Support

• Budget

• Reporting

• Feedback

8

Management Buy-in

Page 9: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• Not training

• Addresses concepts and behaviors

• Terminology

• Informational

9

What is Awareness?

Page 10: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

10

Best Asset/Biggest Vulnerability

Page 11: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• Strategy and Plan• Feedback from key groups• Assess current materials

• Create a baseline• Review current metrics• Analysis of findings and

recommendations• Current trends

• Prioritize

• Schedule, but remain flexible

• Make it “So Number One”

11

Create the Awareness Plan

Page 12: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

12

Ransomware

Page 13: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

Awareness

13

We Are Done, Right?

Page 14: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

14

We Are Done, Right?

Awareness

Training

Page 15: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• End users

• IT

• Executives

• Everyone

• Training everyone equally doesn’t always mean training everyone the same way.

Stay flexible15

Who Needs Training?

Page 16: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• In-house

• LMS

• Outsource

16

Where Does Training Come From?

Page 17: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

17

NOW We Are Done, Right?Awareness

TrainingTesting & Education

Page 18: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

• Measure your success

• Report your success to management

• Remember, stay flexible

• Prioritize weak points, add new content

• Continue the cycle

18

Why Test Me?

Page 19: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

1. Obtain Management buy-in

2. Create your awareness plan based on your IT Security Program

3. Generate a security baseline and prioritize

4. Train everyone

5. Test everyone

6. Stay flexible and prioritize

19

Participant Challenge

Page 20: Employee Security Awareness - WECC Security Awareness... · • Staff responsibilities • IT/Security responsibilities. 3. Establish Processes • Monitor the program • Review

Contact:Lou StramaglioIT Ops [email protected]

20